Analytics BIOC Informational

Unusual exec into a Kubernetes Pod

An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Container Administration Command (T1609)
Detector tags: Kubernetes - API
Attacker's goals:

Execute commands within the Kubernetes Pod. Access any resource the Kubernetes Pod has access to.

Investigative actions:

Check the identity's role designation in the organization. Inspect for any additional suspicious activities inside the Kubernetes Pod.

Test period:
N/A (single event)
Deduplication:
5 Days
5 variations:
  • Failed exec attempt into a Kubernetes Pod Informational
  • First time execution into Kubernetes Pod at the cluster-level Medium (parent: Informational)
  • Identity executed into Kubernetes Pod for the first time Low (parent: Informational)
  • Identity executed into a Kubernetes namespace for the first time Low (parent: Informational)
  • Identity executed into a Kubernetes Pod for the first time Low (parent: Informational)